User Story
As a user creating a sandbox from an uncached image, I want image preparation to have a documented time budget separate from policy repair, so that a slow first setup can complete without disabling bounded failure handling.
Problem Statement
The first recorded large bootstrap exceeded the gateway's 300-second provisioning repair window before Ready. That window currently includes cold image preparation. It was introduced for durable configuration/admission repair, so increasing the CLI wait would not address this failure.
Impact / Why This Matters
A valid first-time setup can fail while downloading or preparing its image. Users may need to choose a smaller bootstrap or repeat preparation, even though no policy error required repair.
Proposed Design
Expose and persist image preparation as a bounded phase distinct from supervisor admission and policy repair. Show the current phase and reason for timeout. Transition only on trusted progress for the current attempt and preserve an absolute preparation ceiling. After that transition, retain the existing repair-window behavior for real configuration changes. Restarts, duplicate progress and no-op settings writes must not extend preparation indefinitely.
Acceptance Criteria
Alternatives Considered
Raising the global 300-second constant changes policy-repair behavior for every attempt. Increasing only the CLI wait cannot alter the gateway deadline. Preparing every image manually can avoid a cold create but does not provide a repeatable default setup.
Agent Investigation
No response
Checklist
User Story
As a user creating a sandbox from an uncached image, I want image preparation to have a documented time budget separate from policy repair, so that a slow first setup can complete without disabling bounded failure handling.
Problem Statement
The first recorded large bootstrap exceeded the gateway's 300-second provisioning repair window before Ready. That window currently includes cold image preparation. It was introduced for durable configuration/admission repair, so increasing the CLI wait would not address this failure.
Impact / Why This Matters
A valid first-time setup can fail while downloading or preparing its image. Users may need to choose a smaller bootstrap or repeat preparation, even though no policy error required repair.
Proposed Design
Expose and persist image preparation as a bounded phase distinct from supervisor admission and policy repair. Show the current phase and reason for timeout. Transition only on trusted progress for the current attempt and preserve an absolute preparation ceiling. After that transition, retain the existing repair-window behavior for real configuration changes. Restarts, duplicate progress and no-op settings writes must not extend preparation indefinitely.
Acceptance Criteria
Alternatives Considered
Raising the global 300-second constant changes policy-repair behavior for every attempt. Increasing only the CLI wait cannot alter the gateway deadline. Preparing every image manually can avoid a cold create but does not provide a repeatable default setup.
Agent Investigation
No response
Checklist